Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-19846 1 Joomla 1 Joomla\! 2019-12-18 7.5 HIGH 9.8 CRITICAL
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
CVE-2018-7282 1 Titool 1 Printmonitor 2019-12-18 7.5 HIGH 9.8 CRITICAL
The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi.
CVE-2009-5026 2 Mysql, Oracle 2 Mysql, Mysql 2019-12-17 6.8 MEDIUM N/A
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.
CVE-2007-5646 1 Simple Machines 1 Simple Machines Forum 2019-12-17 6.8 MEDIUM N/A
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php.
CVE-2019-14314 1 Imagely 1 Nextgen Gallery 2019-12-16 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.
CVE-2013-5743 1 Zabbix 1 Zabbix 2019-12-16 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
CVE-2014-7257 1 Dbd\ 1 \ 2019-12-16 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in DBD::PgPP 0.05 and earlier
CVE-2019-15933 1 Intesync 1 Solismed 2019-12-13 7.5 HIGH 9.8 CRITICAL
Intesync Solismed 3.3sp has SQL Injection.
CVE-2017-14848 1 Dasinfomedia 1 Wphrm Human Resource Management System 2019-12-11 6.5 MEDIUM 8.8 HIGH
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
CVE-2019-19245 1 Napc 1 Xinet Elegant 6 Asset Library 2019-12-11 7.5 HIGH 9.8 CRITICAL
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.
CVE-2015-3424 1 Accentis 1 Content Resource Management System 2019-12-11 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.
CVE-2018-6393 1 Sangoma 1 Freepbx 2019-12-10 6.5 MEDIUM 7.2 HIGH
** DISPUTED ** FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disputes this issue because it is intentional that a user can "directly modify SQL tables ... [or] run shell scripts ... once ... logged in to the administration interface; there is no need to try to find input validation errors."
CVE-2011-1939 3 Debian, Php, Zend 3 Debian Linux, Php, Zend Framework 2019-12-10 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.
CVE-2013-2745 2 Debian, Minidlna Project 2 Debian Linux, Minidlna 2019-12-10 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0
CVE-2019-15995 1 Cisco 1 Dna Spaces\ 2019-12-09 5.5 MEDIUM 6.5 MEDIUM
A vulnerability in the web UI of Cisco DNA Spaces: Connector could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit this vulnerability by entering malicious SQL statements in an affected field in the web UI. A successful exploit could allow the attacker to remove the SQL database, which would require the reinstallation of the Connector VM.
CVE-2019-4387 1 Ibm 1 Sterling B2b Integrator 2019-12-09 6.5 MEDIUM 8.8 HIGH
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 162715.
CVE-2019-15300 1 Centreon 1 Centreon Web 2019-12-09 6.5 MEDIUM 8.8 HIGH
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.
CVE-2019-15972 1 Cisco 1 Unified Communications Manager 2019-12-09 6.5 MEDIUM 8.8 HIGH
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database.
CVE-2011-3584 1 Guidestar 1 Wec Discussion Forum 2019-12-05 7.5 HIGH 9.8 CRITICAL
The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input.
CVE-2011-3583 1 Typo3 1 Typo3 2019-12-05 7.5 HIGH 9.8 CRITICAL
It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability. This issue can only be exploited if two or more parameters are bound to the query and at least two come from user input.
CVE-2019-18662 1 Youphptube 1 Youphptube 2019-12-04 7.5 HIGH 9.8 CRITICAL
An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query. This can be exploited by malicious users to, e.g., read sensitive data from the database through in-band SQL Injection attacks. Successful exploitation of this vulnerability requires the Live Chat plugin to be enabled.
CVE-2019-19016 1 Titanhq 1 Webtitan 2019-12-04 5.0 MEDIUM 7.5 HIGH
An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration interface are vulnerable to SQL Injection through the results parameter. This could be used by an attacker to extract sensitive information from the appliance database.
CVE-2019-19250 1 Opentrade Project 1 Opentrade 2019-12-04 7.5 HIGH 9.8 CRITICAL
OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.
CVE-2018-10759 1 Projectpier 1 Projectpier 2019-12-03 7.5 HIGH 9.8 CRITICAL
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter.
CVE-2019-19113 1 Newbee-mall Project 1 Newbee-mall 2019-12-03 7.5 HIGH 9.8 CRITICAL
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.
CVE-2019-12570 1 Xpertsol 1 Server Status By Hostname\/ip 2019-12-02 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an authenticated user to execute arbitrary SQL commands via GET parameters.
CVE-2019-19207 1 Rconfig 1 Rconfig 2019-11-26 6.5 MEDIUM 8.8 HIGH
rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.
CVE-2019-18890 2 Debian, Redmine 2 Debian Linux, Redmine 2019-11-26 4.0 MEDIUM 6.5 MEDIUM
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
CVE-2013-2091 1 Dolibarr 1 Dolibarr 2019-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
CVE-2019-10766 1 Pixie Project 1 Pixie 2019-11-20 7.5 HIGH 9.8 CRITICAL
Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
CVE-2019-12989 1 Citrix 2 Netscaler Sd-wan, Sd-wan 2019-11-20 7.5 HIGH 9.8 CRITICAL
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
CVE-2019-3661 1 Mcafee 1 Advanced Threat Defense 2019-11-15 6.5 MEDIUM 8.8 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database commands via carefully constructed time based payloads.
CVE-2019-0393 1 Sap 1 Quality Management 2019-11-15 4.0 MEDIUM 4.3 MEDIUM
An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.
CVE-2019-2196 1 Google 1 Android 2019-11-15 4.9 MEDIUM 5.5 MEDIUM
In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135269143
CVE-2019-2198 1 Google 1 Android 2019-11-15 4.9 MEDIUM 5.5 MEDIUM
In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135270103
CVE-2019-12720 1 Auo 1 Sunveillance Monitoring System \& Data Recorder 2019-11-15 5.0 MEDIUM 7.5 HIGH
AUO SunVeillance Monitoring System before v1.1.9e is vulnerable to mvc_send_mail.aspx (MailAdd parameter) SQL Injection. An Attacker can carry a SQL Injection payload to the server, allowing the attacker to read privileged data. This also affects the picture_manage_mvc.aspx plant_no parameter, the swapdl_mvc.aspx plant_no parameter, and the account_management.aspx Text_Postal_Code and Text_Dis_Code parameters.
CVE-2019-2211 1 Google 1 Android 2019-11-14 7.8 HIGH 7.5 HIGH
In createProjectionMapForQuery of TvProvider.java, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135269669
CVE-2019-18646 1 Untangle 1 Ng Firewall 2019-11-14 6.5 MEDIUM 7.2 HIGH
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.
CVE-2011-2936 1 Elgg 1 Elgg 2019-11-12 7.5 HIGH 9.8 CRITICAL
Elgg through 1.7.10 has a SQL injection vulnerability
CVE-2019-10852 1 Computrols 1 Computrols Building Automation Software 2019-11-12 6.5 MEDIUM 8.8 HIGH
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.
CVE-2019-12385 1 Ampache 1 Ampache 2019-11-11 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.
CVE-2019-13079 1 Quest 1 Kace Systems Management Appliance 2019-11-07 6.5 MEDIUM 8.8 HIGH
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /adminui/history_log.php. The affected parameter is TYPE_NAME.
CVE-2019-13078 1 Quest 1 Kace Systems Management Appliance 2019-11-07 6.5 MEDIUM 8.8 HIGH
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /common/user_profile.php. The affected parameter is sort_column.
CVE-2019-13076 1 Quest 1 Kace Systems Management Appliance 2019-11-07 6.5 MEDIUM 8.8 HIGH
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /userui/ticket_list.php, and affected parameters are order[0][column] and order[0][dir].
CVE-2019-12918 1 Quest 1 Kace Systems Management Appliance 2019-11-07 7.5 HIGH 9.8 CRITICAL
Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].
CVE-2019-8127 1 Magento 1 Magento 2019-11-07 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to an account with Newsletter Template editing permission could exfiltrate the Admin login data, and reset their password, effectively performing a privilege escalation.
CVE-2019-8130 1 Magento 1 Magento 2019-11-07 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with store manipulation privileges can execute arbitrary SQL queries by getting access to the database connection through group instance in email templates.
CVE-2019-8134 1 Magento 1 Magento 2019-11-07 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with marketing privileges can execute arbitrary SQL queries in the database when accessing email template variables.
CVE-2019-8143 1 Magento 1 Magento 2019-11-06 4.0 MEDIUM 6.5 MEDIUM
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.
CVE-2019-18784 1 Salesagility 1 Suitecrm 2019-11-06 7.5 HIGH 9.8 CRITICAL
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.